by epianalysis
We often hear that poverty and inequality contribute to poor health, but how much difference do they actually make? More than smoking? Less than fast food?
Over the past few weeks, three landmark papers have emerged that actually quantify how much social factors affect the health of Americans. One study manages to put numbers on the “upstream social determinants” of ill health–from racial segregation to low education; another compares the costs and benefits of neighborhood health improvements with expanded health insurance or more preventive medical care; and the third finally answers the question of how much health insurance coverage actually makes a difference to the lives of the poor. In this week’s blog, we look at how researchers attach numbers to “social factors” behind ill health, and quantify how community-based public health efforts stack-up to the latest drug or medical invention.
The mechanisms explaining why neighborhood social factors contribute to ill health are often called “complex and difficult to individually isolate”; how can we truly tell that a heart attack resulted from being pushed out to a semi-industrial neighborhood without access to a doctor or a quality grocery store? How do we calculate whether this segregation was more pertinent to a person’s death than just the “proximal” factors–that they ate a high-fat diet, or didn’t get treatment for their high blood pressure? The challenge of addressing the “social determinants of health” (whose classic framework for analysis is depicted in the diagram below) is that identifying those determinants requires us to capture a lot of real-world complexities in specific detail, so that we can move from the most immediate pathology of disease (fatty diet = cholesterol = heart attacks), that are straightforward to establish in laboratories and clinical trials, to the risk factors that make pathology possible in the real-world (segregation = poor grocery stores = fast food).
Calculating the PAF
In 1993, two researchers at the U.S. Department of Health and Human Services took the first step towards zooming-out to identify the social determinants of health, when they published a landmark paper in the Journal of the American Medical Association (JAMA), entitled “Actual Causes of Death in the United States“. The paper had a simple premise: to calculate how many American deaths could be attributed to non-genetic factors. They identified deaths from tobacco (an estimated 400,000 deaths), diet and activity patterns (300,000 deaths), alcohol (100,000), microbial agents (90,000), toxic agents (60,000), firearms (35,000), sexual behavior (30,000), motor vehicles (25,000), and illicit use of drugs (20,000). While the details of how they arrived at these numbers are described further below, the paper created furor not because the numbers are surprising (in this day and age, the idea that half of deaths in the U.S. stem from non-genetic factors, and mostly from diet and tobacco, is not surprising), but because the paper came out in the early 1990′s, when much of the medical establishment thought that mapping the human genome and discovering the right medications would solve the country’s health problems.
A few weeks ago, researchers at Columbia University zoomed out further: they recognized that alcohol, tobacco, and similar social pathologies are strongly related to the types of neighborhoods and families that people live around. So they went to the literature and asked: how much do the “big social factors” in neighborhoods–poverty, inequality, education–make a difference in numerical terms?
To calculate the number of deaths attributable to a social factor, they first estimated the relative risk (RR) of death associated with each factor. The relative risk is a ratio of the probability that you’ll die after exposure to a given factor (like tobacco) divided by the probability you’ll die if you’re not exposed to that factor. The researchers reviewed 478 previous studies and compared dichotomous categories of people–those who smoke tobacco and those who don’t, for example–to compare their death rates and calculate a relative risk of death from each factor. They then looked at how common that social factor was in the United States (e.g., the prevalence of tobacco smoking) to calculate the “population attributable fraction” (PAF) of deaths for each social factor. This is calculated as PAF = p(RR-1)/[p(RR-1)+1]. (Want to see where this formula comes from? Take a look at this derivation).
The PAF is the proportional reduction in mortality that would occur if exposure to a risk factor were eliminated (e.g., the number or percentage of deaths that would be avoided if no one smoked tobacco). Many diseases are caused by multiple risk factors, and individual risk factors may interact to produce an overall impact on disease. As a result, PAFs for individual risk factors often overlap and add up to more than 100%. We interpret the PAF as the number of deaths that would be eliminated if the risk factor were removed, not as the number of deaths that will occur if that risk factor were introduced into a new country (where the environment in which that factor works is different), or the numbers of deaths for which that risk factor is the only cause (it’s not that the PAF is the number of deaths caused by that risk factor and no other factors, but rather, the PAF deaths are those that we’d expect to be eliminated if the risk factor were removed from the given social environment). So do you have to adjust for all the “confounding” factors, like the fact that tobacco is related to poverty and a million other causes of ill health? No, in fact you shouldn’t “adjust” for confounders if you’re using the above PAF formula, because the adjustment would affect the RR ratio calculation differently in the numerator than in the denominator, producing bias (to see in detail why the unadjusted RR is preferable, see this paper).
The Columbia University researchers calculated the PAFs of major social factors in the U.S., and here’s what they found: approximately 245,000 deaths in the United States in 2000 were attributable to low education; 176,000 to racial segregation; 162,000 to low social support; 133,000 to individual-level poverty; 119,000 to income inequality; and 39,000 to area-level (neighborhood) poverty.
How does that compute in the grand scheme of things? The number of deaths attributable to low education is actually higher than the number caused by heart attacks (192,898), which were the leading cause of death in the U.S. in the year 2000. The number of deaths attributable to racial segregation is also higher than the number of deaths from stroke (167,661), the third leading cause of death in 2000, and the number of deaths attributable to low social support is comparable to deaths from lung cancer (155,521).
Calculating the bottom line
One of the principal arguments against intervening in the “social determinants of health”, however, is that addressing these factors is likely to cost more than paying for healthcare. It’s easier to give a cholesterol pill to prevent a heart attack, and much harder to address racial segregation. While perhaps this is true on a political level, the epidemiological feasibility and costs of addressing neighborhood determinants of health were addressed by another recent paper, published by leaders of the “Syndemics Prevention Network” at the Centers for Disease Control and Prevention (CDC).
That paper, recently published in the journal Health Affairs, uses a mathematical model of the US health system that features several hundred interacting elements describing the relationships at the national level that affect population health status, health equity, and health care costs over time. The model was used to compare three scenarios that are based on interventions that have been tested in the real world: (1) extending health insurance to all people (similar to the program in Massachusetts); (2) delivering better preventive medical care (simulating that doctors adhere more to guidelines for preventive and chronic medical care); and (3) enabling healthier behavior and improved neighborhood environments for health through a set of cost-effective measures that have been implemented before (ranging from smoking cessation programs to physical activity programs). They called these three interventions the “coverage”, “care” and “protection” interventions, respectively.
Even under a wide range of alternative scenarios, and after accounting for various uncertainties and pessimistic possibilities through sensitivity analysis, the authors found a consistent result: after 25 years, the coverage intervention would be expected to prevent about 880,000 deaths; the care intervention, 3.4 million; and the protection intervention, 4.5 million. The coverage intervention would increase cumulative costs by $1.513 trillion, and the care intervention would increase them by $1.134 trillion. In contrast, the protection intervention would save $596 billion.
Individually, both coverage and care would increase costs by increasing health care use and amplifying the cost-increasing impacts of price inflation and population aging. Protection, on the other hand, would increase total costs for the first six years, reflecting the program’s initial expenses, but would thereafter decrease total costs as program costs declined and disease and injury rates were reduced.
The Oregon health insurance experiment
That’s not to say that health insurance is a bad thing, or that only neighborhood social determinants are worth working on. Another recent paper is a major new report from the National Bureau of Economic Research (NBER), which shows that when the poor have medical insurance, they not only find regular doctors and see them more frequently for preventive care, but also end up feeling healthier, less depressed and are better able to maintain financial stability.
Seems obvious, no? Sadly, what would be an obvious conclusion to many lay people has been a subject of hot debate among healthcare analysts up to the time of this study. (Of course, it is interesting that the U.S. has the highest per capita number of healthcare analysts, and some of the shittiest per capita health statistics among developed countries, so maybe the analysts have their heads stuck up somewhere… but I’m not allowed to say that at the University).
It’s actually been debated for a long time whether insurance provides meaningful benefits to poor people, especially during the recent debate on Medicaid cuts. Some analysts argued that insurance isn’t really going to produce much benefit when there’s already a safety net in the form of emergency rooms and free clinics and hospital charity care (though the latter has been questioned after Yale-New Haven Hospital’s debacle). Also, because so many people who qualify for Medicaid have not signed up (probably because it’s so difficult to do so), several analysts argued that expanded coverage wouldn’t produce much benefit.
The NBER study puts many of those criticisms to rest. Previous research couldn’t resolve the question about insurance’s benefits because the people who didn’t have insurance were often in poor neighborhoods and had a number of other confounding issues like substance abuse, such that comparing them to the insured wouldn’t provide a fair comparison according to critics. But in 2008, Oregon had enough money to expand its Medicaid program. For two years, the program had just enough funding for 10,000 new participants. But 90,000 people applied; to be fair, the program decided to perform a lottery to give coverage to the 10,000 people who could get Medicaid during those two years, before the other 80,000 could be covered by the state budget. So for two years, people who were otherwise in similar social circumstances would be randomly assigned to insurance or not insurance–the first randomized control trial of insurance coverage.
The NBER followed these folks, and found that those with Medicaid were 35% more likely to go to a clinic (and 70% more likely to consistently go to one primary care medical home). They were 20% more likely to have their cholesterol checked. Women were 60% more likely to have mammograms. Overall, the group was 40% less likely to say that their health had worsened in the past year than those without insurance. They were also 25% less likely to have an unpaid bill sent to a collection agency and 40% less likely to borrow money or fail to pay other bills because they had to pay medical bills.
The NBER study–like the Columbia University study and the CDC model–attaches some numbers to what doctors and nurses see every day: the value of social protections for health, and the heavy risks that social realities bear on the ill. What they also highlight, however, is just how out-of-touch mainstream medical research seems to be from the daily problems facing the poor: while we focus on new genetics and the most expensive medical innovations, the real “bang for the buck” appears to be at the neighborhood and political level, not just in molecular biology.
20110806
How many Americans die from racial segregation? About 176,000 a year.
Taiwan: Blogger fined $7K, jailed for 30 days over negative noodle review
From the Taipei Times:
After visiting a Taichung beef noodle restaurant in July 2008, where she had dried noodles and side dishes, Liu wrote that the restaurant served food that was too salty, the place was unsanitary because there were cockroaches and that the owner was a "bully" because he let customers park their cars haphazardly, leading to traffic jams.The restaurant owner, who sounds like a total dick (I can say this because I'm not in Taiwan!), said "he hoped the case would teach her a lesson."
Again, from the Taipei Times:
Huang Cheng-lee (黃呈利), a lawyer in Taichung, said that bloggers who post food reviews should remember to be truthful in their commentary and supplement their comments with photographs to protect themselves.
The $300 Million Button
By Jared M. Spool
[While Luke Wroblewski was writing his well-received book, Web Form Design: Filling in the Blanks, he asked if I could think of an example where a change in a form's design made a noticeable difference in business. "You mean like $300 million of new revenue?" I responded. "Yes, like that." said Luke. So I wrote this article, which he published in his book.]
How Changing a Button Increased a Site's Annual Revenues by $300 Million
It's hard to imagine a form that could be simpler: two fields, two buttons, and one link. Yet, it turns out this form was preventing customers from purchasing products from a major e-commerce site, to the tune of $300,000,000 a year. What was even worse: the designers of the site had no clue there was even a problem.
The form was simple. The fields were Email Address and Password. The buttons were Login and Register. The link was Forgot Password. It was the login form for the site. It's a form users encounter all the time. How could they have problems with it?
The problem wasn't as much about the form's layout as it was where the form lived. Users would encounter it after they filled their shopping cart with products they wanted to purchase and pressed the Checkout button. It came before they could actually enter the information to pay for the product.
The team saw the form as enabling repeat customers to purchase faster. First-time purchasers wouldn't mind the extra effort of registering because, after all, they will come back for more and they'll appreciate the expediency in subsequent purchases. Everybody wins, right?
"I'm Not Here To Be In a Relationship"
We conducted usability tests with people who needed to buy products from the site. We asked them to bring their shopping lists and we gave them the money to make the purchases. All they needed to do was complete the purchase.
We were wrong about the first-time shoppers. They did mind registering. They resented having to register when they encountered the page. As one shopper told us, "I'm not here to enter into a relationship. I just want to buy something."
Some first-time shoppers couldn't remember if it was their first time, becoming frustrated as each common email and password combination failed. We were surprised how much they resisted registering.
Without even knowing what was involved in registration, all the users that clicked on the button did so with a sense of despair. Many vocalized how the retailer only wanted their information to pester them with marketing messages they didn't want. Some imagined other nefarious purposes of the obvious attempt to invade privacy. (In reality, the site asked nothing during registration that it didn't need to complete the purchase: name, shipping address, billing address, and payment information.)
Not So Good For Repeat Customers Either
Repeat customers weren't any happier. Except for a very few who remembered their login information, most stumbled on the form. They couldn't remember the email address or password they used. Remembering which email address they registered with was problematic - many had multiple email addresses or had changed them over the years.
When a shopper couldn't remember the email address and password, they'd attempt at guessing what it could be multiple times. These guesses rarely succeeded. Some would eventually ask the site to send the password to their email address, which is a problem if you can't remember which email address you initially registered with.
(Later, we did an analysis of the retailer's database, only to discover 45% of all customers had multiple registrations in the system, some as many as 10. We also analyzed how many people requested passwords, to find out it reached about 160,000 per day. 75% of these people never tried to complete the purchase once requested.)
The form, intended to make shopping easier, turned out to only help a small percentage of the customers who encountered it. (Even many of those customers weren't helped, since it took just as much effort to update any incorrect information, such as changed addresses or new credit cards.) Instead, the form just prevented sales - a lot of sales.
The $300,000,000 Fix
The designers fixed the problem simply. They took away the Register button. In its place, they put a Continue button with a simple message: "You do not need to create an account to make purchases on our site. Simply click Continue to proceed to checkout. To make your future purchases even faster, you can create an account during checkout."
The results: The number of customers purchasing went up by 45%. The extra purchases resulted in an extra $15 million the first month. For the first year, the site saw an additional $300,000,000.
On my answering machine is the message I received from the CEO of the $25 billion retailer, the first week they saw the new sales numbers from the redesigned form. It's a simple message: "Spool! You're the man!" It didn't need to be a complex message. All we did was change a button.
Website Blocking - Off The Table in the UK (For Now)
In countries across the world, IP rightholders are pushing website blocking as the latest weapon against online copyright infringement. United Nations’ Human Rights experts, security engineers, law professors and others are pushing back, noting both the enormous collateral damage such blocking can cause and the likelihood that it will do little to actually curb infringement.
Against this background, the UK government’s announcement on Wednesday that it will not go forward with a highly controversial website blocking regime - at least for the time being - is an important step in the right direction. Unfortunately, this is unlikely to be the end of the debate in the UK, if Freedom of Information documents and news reports about comments made by UK Minister for Communications, Culture and the Creative Industries Ed Vaizey are any indication.
The UK government’s decision was based on a report by UK regulator Ofcom, dated 27 May 2011, but released on Wednesday as part of the UK government’s welcome response to the landmark Hargreaves report from May. As we saw in last week’s Newzbin2 judgment, rightsholders in the UK already have the ability under existing law to obtain court injunctions requiring ISPs to block websites proven to have infringed copyright, but the reserved blocking powers in sections 17-18 of the 2010 Digital Economy Act are broader and more controversial. That’s why the UK Department of Culture, Media and Sports asked Ofcom in February to review whether those website blocking provisions were workable. Ofcom concluded they weren’t, but did not reject use of website-blocking altogether.
Ofcom’s report considers the technical feasibility of four techniques that Internet intermediaries could use to block sites (Internet Protocol blocking, Domain Name System alteration, URL blocking, and Packet Inspection of network traffic) against 7 criteria: speed of implementation; cost, blocking effectiveness; difficulty of circumvention by users and counter measures ISPs could take; ease of administrative or judicial process; the integrity of network performance; and the level of granularity of blocking that is possible and corresponding impact on legitimate services. Some of this analysis was redacted in the report released by the UK DCMS on Wednesday but an unredacted version of the Ofcom report has now been posted here.
Ofcom concludes that while it is feasible to “constrain access to prohibited locations on the Internet” using these techniques alone or in combination, “none of the techniques is 100% effective; each carries different costs and has a different impact on network performance and the risk of over-blocking” and that “[f]or all blocking methods circumvention by site operators and Internet users is technically possible and would be relatively straightforward by determined users.”
This, of course, is not news to anyone who has taken the time to investigate what is involved in website blocking.
Despite all that, Ofcom concludes that website blocking could form ”part of a broader package of measures to tackle infringement”:
“Although imperfect and technically challenging, site blocking could nevertheless raise the costs and undermine the viability of at least some infringing sites, while also introducing barriers for users wishing to infringe. Site blocking is likely to deter casual and unintentional infringers and by requiring some degree of active circumvention raise the threshold even for determined infringers.”The report goes on to suggest that if blocking is to be implemented, DNS blocking is the preferable approach because it would cause the least delay and cost – two of the key concerns voiced by copyright holders. It also suggests augmenting this by requiring search engines to delist websites.
However, Ofcom notes that DNS blocking is at best a short term solution because implementation of DNS Security Extensions (DNSSEC) will shortly make DNS blocking more transparent and hence less effective. It therefore recommends Packet Inspection for a longer term solution but highlights that it is technically complicated (and therefore slower to implement), expensive (translation: Internet access costs are likely to go up as costs are passed onto subscribers), and raises a number of pesky legal questions – such as whether DPI is compatible with UK privacy and data protection law. (We’d like to read that legal opinion).
After IP righstholders’ intense lobbying for PIPA in the US and the concerted push in international fora (such as WIPO and the OECD) for Internet intermediaries to act as copyright police and engage in website blocking, it is heartening to see the UK regulator’s sensible discussion of the technological limitations, and awareness of the public policy implications of ordering Internet intermediaries to comb through our online communications.
We welcome the UK government’s announcement, and commend its commitment to evidence-based policy-making. Let’s hope that policymakers across the world take the time to understand the implications for all Internet users’ security, for human rights and the rule of law, and the future of the open global Internet of telling DNS servers to “lose” parts of the Internet in the name of enforcing copyright holders’ private rights.
Know Your Rights!
By Hanni Fakhoury
Know Your Rights Whitepaper (pdf)
EFF Police Tips (pdf)
Your computer, your phone, and your other digital devices hold vast amounts of personal information about you and your family. This is sensitive data that's worth protecting from prying eyes - including those of the government.
The Fourth Amendment to the Constitution protects you from unreasonable government searches and seizures, and this protection extends to your computer and portable devices. But how does this work in the real world? What should you do if the police or other law enforcement officers show up at your door and want to search your computer?
EFF has designed this guide to help you understand your rights if officers try to search the data stored on your computer or portable electronic device, or seize it for further examination somewhere else.
Because anything you say can be used against you in a criminal or civil case, before speaking to any law enforcement official, you should consult with an attorney.
| Q: | Can the police enter my home to search my computer or portable device, like a laptop or cell phone? | |||
| A: | No, in most instances, unless they have a warrant. But there are two major exceptions: (1) you consent to the search;1 or (2) the police have probable cause to believe there is incriminating evidence on the computer that is under immediate threat of destruction.2 |
| Q: | What if the police have a search warrant to enter my home, but not to search my computer? Can they search it then? | |
| A: | No, typically, because a search warrant only allows the police to search the area or items described in the warrant.3 But if the warrant authorizes the police to search for evidence of a particular crime, and such evidence is likely to be found on your computer, some courts have allowed the police to search the computer without a warrant.4 Additionally, while the police are searching your home, if they observe something in plain view on the computer that is suspicious or incriminating, they may take it for further examination and can rely on their observations to later get a search warrant.5 And of course, if you consent, any search of your computer is permissible. |
| Q: | Can my roommate/guest/spouse/partner allow the police access to my computer? |
| A: | Maybe. A third party can consent to a search as long as the officers reasonably believe the third person has control over the thing to be searched.6 However, the police cannot search if one person with control (for example a spouse) consents, but another individual (the other spouse) with control does not.7 One court, however, has said that this rule applies only to a residence, and not personal property, such as a hard drive placed into someone else's computer.8 |
| Q: | What if the police want to search my computer, but I'm not the subject of their investigation? |
| A: | It typically does not matter whether the police are investigating you, or think there is evidence they want to use against someone else located on your computer. If they have a warrant, you consent to the search, or they think there is something incriminating on your computer that may be immediately destroyed, the police can search it. Regardless of whether you're the subject of an investigation, you can always seek the assistance of a lawyer. |
| Q: | Can I see the warrant? |
| A: | Yes. The police must take the warrant with them when executing it and give you a copy of it.9 They must also knock and announce their entry before entering your home10 and must serve the warrant during the day in most circumstances.11 |
| Q: | Can the police take my computer with them and search it somewhere else? |
| A: | Yes. As long as the police have a warrant, they can seize the computer and take it somewhere else to search it more thoroughly. As part of that inspection, the police may make a copy of media or other files stored on your computer.12 |
| Q: | Do I have to cooperate with them when they are searching? |
| A: | No, you do not have to help the police conduct the search. But you should not physically interfere with them, obstruct the search, or try to destroy evidence, since that can lead to your arrest. This is true even if the police don't have a warrant and you do not consent to the search, but the police insist on searching anyway. In that instance, do not interfere but write down the names and badge numbers of the officers and immediately call a lawyer. |
| Q: | Do I have to answer their questions while they are searching my home without a warrant? |
| A: | No, you do not have to answer any questions. In fact, because anything you say can be used against you and other individuals, it is best to say nothing at all until you have a chance to talk to a lawyer. However, if you do decide to answer questions, be sure to tell the truth. It is a crime to lie to a police officer and you may find yourself in more trouble for lying to law enforcement than for whatever it was they wanted on your computer.13 |
| Q: | If the police ask for my encryption keys or passwords, do I have to turn them over? |
| A: | No. The police can't force you to divulge anything. However, a judge or a grand jury may be able to. The Fifth Amendment protects you from being forced to give the government self-incriminating testimony. If turning over an encryption key or password triggers this right, not even a court can force you to divulge the information. But whether that right is triggered is a difficult question to answer. If turning over an encryption key or password will reveal to the government information it does not have (such as demonstrating that you have control over files on a computer), there is a strong argument that the Fifth Amendment protects you.14 If, however, turning over passwords and encryption keys will not incriminate you, then the Fifth Amendment does not protect you. Moreover, even if you have a Fifth Amendment right that protects your encryption keys or passwords, a grand jury or judge may still order you to disclose your data in an unencrypted format under certain circumstances.15 If you find yourself in a situation where the police are demanding that you turn over encryption keys or passwords, let EFF know. |
| Q: | If my computer is taken and searched, can I get it back? |
| A: | Perhaps. If your computer was illegally seized, then you can file a motion with the court to have the property returned.16 If the police believe that evidence of a crime has been found on your computer (such as "digital contraband" like pirated music and movies, or digital images of child pornography), the police can keep the computer as evidence. They may also attempt to make you forfeit the computer, but you can challenge that in court.17 |
| Q: | What about my work computer? |
| A: | It depends. Generally, you have some Fourth Amendment protection in your office or workspace.18 This means the police need a warrant to search your office and work computer unless one of the exceptions described above applies. But the extent of Fourth Amendment protection depends on the physical details of your work environment, as well as any employer policies. For example, the police will have difficulty justifying a warrantless search of a private office with doors and a lock and a private computer that you have exclusive access to. On the other hand, if you share a computer with other co-workers, you will have a weaker expectation of privacy in that computer, and thus less Fourth Amendment protection.19 However, be aware that your employer can consent to a police request to search an office or workspace.20 Moreover, if you work for a public entity or government agency, no warrant is required to search your computer or office as long as the search is for a non-investigative, work-related matter.21 |
| Q: | I've been arrested. Can the police search my cell phone without a warrant? |
| A: | Maybe. After a person has been arrested, the police generally may search the items on her person and in her pockets, as well as anything within her immediate control.22 This means that the police can physically take your cell phone and anything else in your pockets. Some courts go one step further and allow the police to search the contents of your cell phone, like text messages, call logs, emails, and other data stored on your phone, without a warrant.23 Other courts disagree, and require the police to seek a warrant.24 It depends on the circumstances and where you live. |
| Q: | The police pulled me over while I was driving. Can they search my cell phone? |
| A: | Maybe. If the police believe there is probably evidence of a crime in your car, they may search areas within a driver or passenger's reach where they believe they might find it - like the glove box, center console, and other "containers."25 Some courts have found cell phones to be "containers" that police may search without a warrant.26 |
| Q: | Can the police search my computer or portable devices at the border without a warrant? |
| A: | Yes. So far, courts have ruled that almost any search at the border is "reasonable" - so government agents don't need to get a warrant. This means that officials can inspect your computer or electronic equipment, even if they have no reason to suspect there is anything illegal on it.27 An international airport may be considered the functional equivalent of a border, even if it is many miles from the actual border.28 |
| Q: | Can the police take my electronic device away from the border or airport for further examination without a warrant? |
| A: | At least one federal court has said yes, they can send it elsewhere for further inspection if necessary.29 Even though you may be permitted to enter the country, your computer or portable device may not be. |
Spanish Court Rules That Linking to Potential Copyright Infringing Material Is Not Copyright Infringement
by Oscar Montezuma Panez
We all know that HTML links are the heart of the World Wide Web. What many don’t appreciate is that legal liability for linking varies greatly across countries. Given the importance of linking to the World Wide Web, whether websites can be held liable for copyright infringement for linking to material that is potentially copyright-infringing is a key issue. While US copyright law has a safe harbor for websites that provide location tools, the European framework for e-commerce does not have a specific limitation on liability for websites that provide links. As a result, courts in different EU member states have developed different standards for linking liability. In recent years, Spanish courts have issued several inconsistent rulings on whether websites containing links to potentially copyright-infringing material on peer-to-peer networks violate copyright owners’ exclusive right under Spanish law of making available copyrighted works. But now a recent decision of the influential Court of Appeals of Barcelona (Audiencia Provincial de Barcelona) in the case of Indice-web has clarified that merely providing a link is not "making available" content, and does not infringe copyright.
The case was brought by the Spanish collecting society Sociedad General de Autores y Editores (SGAE), which sued the owner of Indice-web, a website that provided, among other content, links to potentially copyright infringing content that could be downloaded with P2P software. The court at first instance found that Indice-web was not liable for copyright infringement because it did not host any copyright-infringing content and merely operated as an index of websites, providing only links. If viewers chose to click on the links and download particular content, the content would be transmitted by the third party web server and reproduced on the user’s computer, without any involvement of Indice-web. On that basis, the court denied the provisional measures requested by SGAE—an injunction ordering immediate cessation of making available links to musical works in SGAE's repertoire without permission; seizure of all the proceeds earned by the defendant in the marketing of Indice-web; and the suspension of the services provided by the upstream host of Indice-web.
The court noted that Indice-web merely acts as a guide for users by providing a link to works that could later be downloaded or exchanged through P2P programs. The court also noted that Spanish law does not forbid such guidance or orientation. In this case, the court held that "the linking system does not constitute distribution, nor reproduction nor public communication," under Spanish law.
SGAE appealed the ruling, arguing that the first court’s decision only analyzed the defendant’s conduct regarding provision of links to content accessible via P2P networks, but did not consider other possible bases for copyright infringement liability such as providing assistance for direct downloads and unauthorized streaming of copyrighted works hosted on a third party server. The Court of Appeals declined to rule on those questions because they had not been raised by SGAE at first instance. The court clarified that the main issue in question was whether placing a link pointing to content stored on a different server constituted impermissible reproduction, "making available," or communication to the public, under Spain’s copyright law.
The Court of Appeals reaffirmed the reasoning of the previous court and ruled that Indice-web did not violate copyright because it merely provides links and does not participate in hosting or the transmission of potentially copyright-infringing content. It found that: "Providing a link does not imply making available the protected work according to letter i) of article 20.2 of the Intellectual Property Act, and in such sense does not qualify as public communication. Making available the protected work occurs in the computers where the protected work is hosted and where it can be downloaded through P2P networks. In such sense, [it is those] users who make available the protected work." The court also found that Indice-web was not engaged in advertising, or any for profit activities.
Although this ruling is not directly binding outside Spain it is important because it comes from the influential Barcelona Court of Appeals and clarifies the previous inconsistent Spanish rulings. Given the fundamental importance of linking to the World Wide Web, we are heartened to see that the Barcelona Appeals Court and the court of first instance understand Internet architecture and the important policy issues this case raises. We hope other European courts will take a similarly thoughtful approach to these issues going forward.
20110805
Why Facebook and Google's Concept of 'Real Names' Is Revolutionary
By Alexis Madrigal
Should you have to use your real name online? It's an issue that's long simmered among social-media critics and supporters alike. On one end of the spectrum, there's 4chan, where everything is anonymous. On the other, are Facebook and Google Plus. Both have drawn fire for categorically preventing people from using pseudonyms. This week, a new site, My Name Is Me, launched to make the case to allow anyone to use any name they choose.
This has seemed like a niche battle to me: A tiny group of activists complaining about some edge cases while the real-name policies benefited most people by raising the civility of online discourse. On a strictly utilitarian basis, it seemed like their arguments could be ignored.
But this week's discussions have made me rethink my intuition about names on social networks. My instincts had strongly pointed to requiring real names; my experience in the comment trenches of different websites has led me to believe that pure anonymity online creates a short-circuiting of our social software. It seemed natural to believe that attaching a persistent, real name to one's online identity more accurately modeled our real-world social space.
I've changed my mind. The kind of naming policy that Facebook and Google Plus have is actually a radical departure from the way identity and speech interact in the real world. They attach identity more strongly to every act of online speech than almost any real-world situation does.
I want to walk you through how I've come to this understanding. Because I've been obsessively listening to Philosophy Bites podcasts, I'm going to use a thought experiment.
Imagine you're walking down the street and you say out loud, "Down with the government!" For all non-megastars, the vast majority of people within earshot will have no idea who you are. They won't have access to your employment history or your social network or any of the other things that a Google search allows one to find. The only information they really have about you is your physical characteristics and mode of dress, which are data-rich but cannot be directly or easily connected to your actual identity. In my case, bystanders would know that a 5'9", 165-pound probably Caucasian male with half a beard said, "Down with the government!" Neither my speech or the context in which it occurred is preserved. And as soon as I leave the immediate vicinity, no one can definitively prove that I said, "Down with the government!"
In your head, adjust where you conduct for this thought experiment (you say it at work or your hometown or on television) or what you say (something racist, something intensely valuable, something criminal) or who you are (child, celebrity, politician) or who is listening (reporters, no one, coworkers, family). What I think you'll find is that we have different expectations for the publicness and persistence of a statement depending on a variety of factors. There is a continuum of publicness and persistence and anonymity. But in real life, we expect very few statements to be public, persistent, and attached to your real identity. Basically, only people talking on television or through other media can expect such treatment. And even then, the vast majority of their statements don't become part of the searchable Internet.
Online, Google and Facebook require an inversion of this assumed norm. Every statement you make on Google Plus or Facebook is persistent and strongly attached to your real identity through your name. Both services allow you to change settings to make your statements more or less public, which solves some problems. However, participating in public life on the services requires attaching your name to your statements. On the boulevards and town squares of Facebook, you can't just say, "Don't with the government," with the knowledge that only a small percentage of the people who hear you could connect your statement to you. But the information is still being recorded, presumably in perpetuity. That means that if a government or human-resources researcher or plain old enemy wants to get a hold of it, it is possible.
The pseudonym advocates note that being allowed to pick and choose a different name solves some of these problems. One can choose to tightly couple one's real-world identity and online identity--or not. One can choose to have multiple identities for separate networks. In the language we were using earlier, pseudonyms allow statements to be public and persistent, but not attached to one's real identity.
I can understand why Google and Facebook don't want this to happen. It's bad for their marketing teams. It generates social problems when people don't act responsibly under the cloak of their assumed identity. It messes up the clarity and coherence of their data. And maybe those costs do outweigh the benefits pseudonymity brings to social networks.
But then let's have that conversation. Let's not pretend that what Google and Facebook are doing has long-established precedents and therefore these companies are only doing what they're doing to mimic real life. They are creating tighter links between people's behavior and their identities than has previously existed in the modern world.
“Real Names” Policies Are an Abuse of Power
Everyone’s abuzz with the “nymwars,” mostly in response to Google Plus’ decision to enforce its “real names” policy. At first, Google Plus went on a deleting spree, killing off accounts that violated its policy. When the community reacted with outrage, Google Plus leaders tried to calm the anger by detailing their “new and improved” mechanism to enforce “real names” (without killing off accounts). This only sparked increased discussion about the value of pseudonymity. Dozens of blog posts have popped up with people expressing their support for pseudonymity and explaining their reasons. One of the posts, by Kirrily “Skud” Robert included a list of explanations that came from people she polled, including:
- “I am a high school teacher, privacy is of the utmost importance.”
- “I have used this name/account in a work context, my entire family know this name and my friends know this name. It enables me to participate online without being subject to harassment that at one point in time lead to my employer having to change their number so that calls could get through.”
- “I do not feel safe using my real name online as I have had people track me down from my online presence and had coworkers invade my private life.”
- “I’ve been stalked. I’m a rape survivor. I am a government employee that is prohibited from using my IRL.”
- “As a former victim of stalking that impacted my family I’ve used [my nickname] online for about 7 years.”
- “[this name] is a pseudonym I use to protect myself. My web site can be rather controversial and it has been used against me once.”
- “I started using [this name] to have at least a little layer of anonymity between me and people who act inappropriately/criminally. I think the “real names” policy hurts women in particular.
- “I enjoy being part of a global and open conversation, but I don’t wish for my opinions to offend conservative and religious people I know or am related to. Also I don’t want my husband’s Govt career impacted by his opinionated wife, or for his staff to feel in any way uncomfortable because of my views.”
- “I have privacy concerns for being stalked in the past. I’m not going to change my name for a google+ page. The price I might pay isn’t worth it.”
- “We get death threats at the blog, so while I’m not all that concerned with, you know, sane people finding me. I just don’t overly share information and use a pen name.”
- “This identity was used to protect my real identity as I am gay and my family live in a small village where if it were openly known that their son was gay they would have problems.”
- “I go by pseudonym for safety reasons. Being female, I am wary of internet harassment.”
You’ll notice a theme here…
Another site has popped up called “My Name Is Me” where people vocalize their support for pseudonyms. What’s most striking is the list of people who are affected by “real names” policies, including abuse survivors, activists, LGBT people, women, and young people.
Over and over again, people keep pointing to Facebook as an example where “real names” policies work. This makes me laugh hysterically. One of the things that became patently clear to me in my fieldwork is that countless teens who signed up to Facebook late into the game chose to use pseudonyms or nicknames. What’s even more noticeable in my data is that an extremely high percentage of people of color used pseudonyms as compared to the white teens that I interviewed. Of course, this would make sense…
The people who most heavily rely on pseudonyms in online spaces are those who are most marginalized by systems of power. “Real names” policies aren’t empowering; they’re an authoritarian assertion of power over vulnerable people. These ideas and issues aren’t new (and I’ve even talked about this before), but what is new is that marginalized people are banding together and speaking out loudly. And thank goodness.
What’s funny to me is that people also don’t seem to understand the history of Facebook’s “real names” culture. When early adopters (first the elite college students…) embraced Facebook, it was a trusted community. They gave the name that they used in the context of college or high school or the corporation that they were a part of. They used the name that fit into the network that they joined Facebook with. The names they used weren’t necessarily their legal names; plenty of people chose Bill instead of William. But they were, for all intents and purposes, “real.” As the site grew larger, people had to grapple with new crowds being present and discomfort emerged over the norms. But the norms were set and people kept signing up and giving the name that they were most commonly known by. By the time celebrities kicked in, Facebook wasn’t demanding that Lady Gaga call herself Stefani Germanotta, but of course, she had a “fan page” and was separate in the eyes of the crowd. Meanwhile, what many folks failed to notice is that countless black and Latino youth signed up to Facebook using handles. Most people don’t notice what black and Latino youth do online. Likewise, people from outside of the US started signing up to Facebook and using alternate names. Again, no one noticed because names transliterated from Arabic or Malaysian or containing phrases in Portuguese weren’t particularly visible to the real name enforcers. Real names are by no means universal on Facebook, but it’s the importance of real names is a myth that Facebook likes to shill out. And, for the most part, privileged white Americans use their real name on Facebook. So it “looks” right.
Then along comes Google Plus, thinking that it can just dictate a “real names” policy. Only, they made a huge mistake. They allowed the tech crowd to join within 48 hours of launching. The thing about the tech crowd is that it has a long history of nicks and handles and pseudonyms. And this crowd got to define the early social norms of the site, rather than being socialized into the norms set up by trusting college students who had joined a site that they thought was college-only. This was not a recipe for “real name” norm setting. Quite the opposite. Worse for Google… Tech folks are VERY happy to speak LOUDLY when they’re pissed off. So while countless black and Latino folks have been using nicks all over Facebook (just like they did on MySpace btw), they never loudly challenged Facebook’s policy. There was more of a “live and let live” approach to this. Not so lucky for Google and its name-bending community. Folks are now PISSED OFF.
Personally, I’m ecstatic to see this much outrage. And I’m really really glad to see seriously privileged people take up the issue, because while they are the least likely to actually be harmed by “real names” policies, they have the authority to be able to speak truth to power. And across the web, I’m seeing people highlight that this issue has more depth to it than fun names (and is a whole lot more complicated than boiling it down to being about anonymity, as Facebook’s Randi Zuckerberg foolishly did).
What’s at stake is people’s right to protect themselves, their right to actually maintain a form of control that gives them safety. If companies like Facebook and Google are actually committed to the safety of its users, they need to take these complaints seriously. Not everyone is safer by giving out their real name. Quite the opposite; many people are far LESS safe when they are identifiable. And those who are least safe are often those who are most vulnerable.
Likewise, the issue of reputation must be turned on its head when thinking about marginalized people. Folks point to the issue of people using pseudonyms to obscure their identity and, in theory, “protect” their reputation. The assumption baked into this is that the observer is qualified to actually assess someone’s reputation. All too often, and especially with marginalized people, the observer takes someone out of context and judges them inappropriately based on what they get online. Let me explain this in a concrete example that many of you have heard before. Years ago, I received a phone call from an Ivy League college admissions officer who wanted to accept a young black man from South Central in LA into their college; the student had written an application about how he wanted to leave behind the gang-ridden community he came from, but the admissions officers had found his MySpace which was filled with gang insignia. The question that was asked of me was “Why would he lie to us when we can tell the truth online?” Knowing that community, I was fairly certain that he was being honest with the college; he was also doing what it took to keep himself alive in his community. If he had used a pseudonym, the college wouldn’t have been able to get data out of context about him and inappropriately judge him. But they didn’t. They thought that their frame mattered most. I really hope that he got into that school.
There is no universal context, no matter how many times geeks want to tell you that you can be one person to everyone at every point. But just because people are doing what it takes to be appropriate in different contexts, to protect their safety, and to make certain that they are not judged out of context, doesn’t mean that everyone is a huckster. Rather, people are responsibly and reasonably responding to the structural conditions of these new media. And there’s nothing acceptable about those who are most privileged and powerful telling those who aren’t that it’s OK for their safety to be undermined. And you don’t guarantee safety by stopping people from using pseudonyms, but you do undermine people’s safety by doing so.
Thus, from my perspective, enforcing “real names” policies in online spaces is an abuse of power.
Judge says domain name loss is not a "substantial hardship"
By Timothy B. Lee
A federal judge has rejected a petition by the Spanish company Puerto 80 for the return of the domain names Rojadirecta.com and Rojadirecta.org. The US federal government seized the domains earlier this year, arguing that they were primarily used to provide links to infringing sporting content.
Puerto 80 says that after weeks of playing phone tag with federal officials, it was told that it could only have the domain names back if it agreed not to "link to any U.S. content anywhere on its sites anywhere in the world." Since this demand clearly exceeded what was required of it under copyright law (and arguably violated the First Amendment), Puerto sued for the return of the domain names.
Under federal law, the owner of seized property can seek its return if the government's continuing to hold it would cause a "substantial hardship" to its owner. Puerto 80 pointed not only to the loss of traffic since the seizure, but also to the infringement of its First Amendment rights. It also pointed out that its activities had already been ruled legal by the Spanish courts.
But Judge Paul Crotty was unconvinced. He replied that Puerto 80 had registered alternative domains like rojadirecta.me and rojadirecta.es, and that Rojadirecta can use its "large Internet presence" to "simply distribute information about its new domain name to its customers."
And he rejected Puerto 80's First Amendment claims because the "main purpose" of the website is to "catalog links to copyrighted athletic events." He wrote that "Puerto 80 may certainly argue this First Amendment issue in its upcoming motion to dismiss, but the First Amendment considerations discussed here certainly do not establish the kind of substantial hardship required to prevail on this petition."
But the Electronic Frontier Foundation's Corynne McSherry says that the Supreme Court has ruled otherwise. "We are aware of no general principle that freedom of speech may be abridged when the speaker’s listeners could come by his message by some other means," the high court wrote in 1976.
"A mere finding of 'probable cause' does not and cannot justify a prior restraint," McSherry writes. "How the court believes that the seizure satisfies the First Amendment in this regard is a mystery."
20110804
Shock, awe: British government agrees that copyright has gone too far
By Timothy B. Lee
The British government today pledged (PDF) to enact significant changes to copyright law, including orphan works reforms and the introduction of new copyright exceptions. And the tone of the comments was surprising: the government agrees that "copyright currently over-regulates to the detriment of the UK." CD (and perhaps DVD) ripping for personal use should become legal at last—and the government is even keen to see that the consumer rights granted by law can't simply be taken away by contract (such as a "EULA" sticker on a CD demanding that a disk not be ripped).
Responding to an independent study done earlier this year, the government has also endorsed the creation of a digital copyright exchange to facilitate licensing. Within limits, the government endorses the view that "the widest possible exceptions to copyright within the existing EU framework are likely to be beneficial to the UK."
The government's report is also significant for what it pledges not to do. The government says it will not bring forward the "site blocking" provisions of last year's Digital Economy Act. This is evidently not referring to the power of copyright holders to compel individual ISPs to block infringing sites after a lawsuit, but to a more comprehensive system whereby the government maintains a list of sites that all ISPs in the country would be required to block.
Probably the most important announcement is the expansion of copyright exceptions. Unlike the US, the UK does not have a broad, judge-made "fair use" doctrine that allows transformative uses of copyrighted works. Today's report doesn't use the phrase "fair use," but it endorses legalizing many of the same ideas. The government proposes to create "a limited private copying exception," to "widen the exception for non-commercial research," to "widen the exception for library archiving," and "to introduce an exception for parody."
Orphan works are out-of-print works that cannot be used by anyone because their copyright holders cannot be found. Legislation to address the problem has languished in the US Congress for years. The British government has now pledged to enact orphan works reform that would allow "both commercial and cultural uses of orphan works," once a prospective user has conducted a diligent search for the copyright holder and paid standard licensing fees.
The report devotes significant attention to the creation of a Digital Copyright Exchange, a centralized clearinghouse to improve the efficiency of copyright licensing efforts. The project is still in the planning phase and participation in the scheme would be voluntary. But the government vows to study ways to encourage and facilitate the creation of an exchange. One way it will do that is by ensuring that the government's own "Crown copyright" works will be available for licensing.
Patents receive only a brief mention in the report. The government pledges to "resist extensions of patents into sectors which are currently excluded unless there is clear evidence of a benefit to innovation and growth." It also promises to investigate the problems created by patent thickets, although it doesn't endorse any specific proposal for addressing the problem.
The report is significant not only for the specific policies it endorses, but also for the shift in tone it represents. For decades, policymakers around the world have steadily expanded the breadth of copyright and patent protections and ratcheted up enforcement. So the fact that the UK's official copyright agenda now consists mostly of creating new copyright exceptions and abandoning previously announced enforcement efforts suggests the pendulum may finally be swinging in the other direction. The individual reforms are important, but it is most significant as a barometer of the shifting political climate.
20110803
Kurt Vonnegut's Slaughterhouse-Five banned by Missouri School
Kurt Vonnegut's celebrated second world war satire censored along with teen novel Twenty Boy Summer
by Sarah Ockler
Kurt Vonnegut's Slaughterhouse-Five and young adult novel Twenty Boy Summer by Sarah Ockler have both been banned from a school curriculum and library in a Missouri school following complaints from a local professor about children being exposed to "shocking material".
Ockler's novel, which tells of a girl's summer romance as she attempts to get over the death of her first love a year earlier, is being removed from the school curriculum and library in Republic, Missouri, along with Kurt Vonnegut's classic novel Slaughterhouse-Five. The ban follows a complaint from Wesley Scroggins, a professor at Missouri State University, who wrote in a column for a local paper last year claiming that Vonnegut's novel "contains so much profane language, it would make a sailor blush with shame". He said that Ockler's book, described by Kirkus Reviews as a "sincere, romantic tearjerker", "glorifies drunken teen parties, where teen girls lose their clothes in games of strip beer pong", and laid into Laurie Halse Anderson's acclaimed novel Speak, which he felt "should be classified as soft pornography".
Scroggins's complaints sparked a review by the district school board, which voted this week to keep Speak but to remove the novels by Vonnegut and Ockler. Twenty Boy Summer focused on "sensationalising sexual promiscuity", Superintendent Vern Minor told the News-Leader. "I just don't think it's a good book. I don't think it's consistent with these standards and the kind of message that we want to send," he said. "If the book had ended on a different note, I might have thought differently." Slaughterhouse-Five, meanwhile, contains "really, really intense" language and does not have "any place in high school", according to Minor.
Following the decision to remove her novel from school shelves in Missouri, Ockler said that "you can ban my books from every damn district in the country — I'm still not going to write to send messages or make teens feel guilty because they've made choices that some people want to pretend don't exist. That's my choice. And I'll never be ashamed of my choice to write about real issues."
Writing on her blog, Ockler was adamant that "not every teen who has sex or experiments with drinking feels remorseful about it. Not every teen who has sex gets pregnant, gets someone pregnant, or contracts an STD. Not every teen who has sex does so while in a serious relationship. Not every teen who has sex outside of a relationship feels guilty, shameful, or regretful later on."
The "crazy train", she added, "has finally derailed" following the Missouri ban. "Look, I've said it before and I'll say it a million times more. I get that my book isn't appropriate for all teens, and that some parents are opposed to the content. That's fine. Read it and decide for your own family. I wish more parents would do that — get involved in their kids' reading and discuss the issues the books portray. But don't make that decision for everyone else's family by limiting a book's availability and burying the issue under guise of a 'curriculum discussion'."
Scroggins, meanwhile, told the News Leader that while it was "unfortunate [the board] chose to keep the other book [Speak] ... I congratulate them for doing what's right and removing the two books".
California judge: trolling with someone else's Facebook is identity theft
By Venkat Balasubramani and Eric Goldman
Venkat Balasubramani's take
Rolando was a juvenile who received an unsolicited text message with the victim's e-mail password. According to the court, he used the password to gain access to the victim's Facebook account and posted several sexually inappropriate messages from the victim's account. The Facebook posts included posts on the walls of the victim's friends and the following change to the victim's profile:Hey, Face Bookers, [sic] I'm [S.], a junior in high school . . . I want to be a pediatrician but I'm not sure where I want to go to college. I have high standards for myself and plan to meet them all. I love to suck dick.The victim testified that she suffered stigma as a result of these and other posts. "I used to love going to school," she said. "Now, I dread dealing with this every day."
The juvenile was prosecuted under a California statute (section 530.55) which applies to anyone who:
wilfully obtains personal identifying information [of the victim and] uses that information for any unlawful purpose, including to obtain, or attempt to obtain, credit, goods, services, real property, or medication information.Did the defendant willfully obtain the victim's "personal identifying information"? The court holds that, despite his argument that he "passively receiv[ed] the text message" which contained the victim's password information, he "willfully" obtained it because he remembered it or otherwise recorded it so he could use it later. Moreover, the court concludes that the defendant willfully obtained the victim's Facebook account password. The record was devoid of evidence as to how exactly the defendant accessed the victim's Facebook account, and in the absence of any such evidence, the court says it's "reasonable to infer" that the defendant reset the victim's Facebook password using her e-mail password and then gained access to the victim's Facebook account.
Did the defendant use the victim's information for an unlawful purpose? In addition to obtaining the information willfully, the perpetrator has to use the information for an "unlawful purpose." The first possibility was that the defendant violated section 647.6, which applies when someone "annoys or molests any child under 18." However, under California Supreme Court precedent, this statute requires a motivation by "an unnatural or abnormal sexual interest in the victim." [emphasis added] The court concluded that the facts did not fit into this statute because the defendant had no real contact with the victim other than the Facebook posts and he also testified that he "intended his comments to be taken as a joke."
The second possibility was that the defendant used the victim's personal information to commit a tortious act. The defendant argued that "unlawful purpose" as used in the statute should be restricted to criminal conduct, but the court disagreed, noting legislative intent to expand the scope of the statute in amending it.
The court also pointed to the fact that the definitions section of the statute included the term "crime," and the legislature chose instead to use "any unlawful purpose." The defendant practically conceded that his conduct satisfied the requirements of a civil defamation claim. The court therefore finds that the defendant's act constituted libel and constituted an "unlawful purpose" under the statute. Alternatively, the court held that the defendant's conduct satisfied the statute because it also constituted a criminal offense. The defendant's actions violated section 653m, which makes illegal any contact with another person using "obscene language... by means of an electronic communication device... with [the] intent to annoy."
It's tough to muster much sympathy for the defendant, who was previously in trouble for reckless driving when he drove his car "at three girls in the school parking lot, but stopped abruptly several feet away from them in an attempt to scare them."
The definition of "personal identifying information" in the statute is broad. (We ran into an analogous problem in the Pineda case). It looks like the court focused on the Facebook password as being the information in question that supported the violation of the statute, but the opinion is not totally clear on this. A broad definition of personal identifying information coupled with the court's decision to allow tortious conduct to satisfy the "unlawful purpose" could lead to a statute that is expansive in scope and which should raise everyone's First Amendment hackles. Given that the defendant used the e-mail password to access Facebook, this does not feel to me like a case that pushed the statute to the limit.
Interestingly, the defendant argued that his conduct would violate California's newly enacted e-personation statute (section 528.5) which was effective January 1, 2011, and the fact that this statute was passed demonstrates that the legislature did not view his conduct as violating the previously existing statute. The court disagrees with this argument, noting that the newly enacted e-personation statute has different elements from section 530.5:
Section 528.5 does not include a requirement that a perpetrator obtain personal identifying information. As a result, a person could violate section 528.5 by merely posting comments on a blog impersonating another person. There is no requirement, under these circumstances, that the person obtain a password—a key distinction.
Yikes. This is precisely what is wrong with California's e-personation statute.
Eric Goldman's take
This case plays out as a Greek-style tragedy in three parts.Part one: Someone sent the victim's e-mail password to the defendant. The court is vague about who did this or how that person got the victim's password.
This brings up one of my modern rules for clean living: never tell anyone else your passwords. Ever. (Another rule for clean living is to constantly change your passwords, but this is harder to obey). I am such a stickler about my passwords that I don't tell them to anyone. Certainly not to campus IT when they want to muck with my computer, but I don't even tell my passwords to my wife. (FWIW, my wife has told me many of her passwords, but I would never use them without her express instructions). I know there's a debate about the spouse-and-passwords dilemma. It's not that I don't trust my wife. I do, completely. But my rule is clean and simple. If someone other than me types in my password, then they ripped it off. (We'll revisit the problem of accessing a logged-in computer in a bit).
In this case, we don't know why the password-obtainer had the victim's password. Perhaps it was hacked. More likely, the victim made an error in judgment. Either way, the defendant apparently used the e-mail password to help reset the Facebook password and access the Facebook account.
Part two: The defendant misused the victim's password. It goes without saying that the defendant had no business logging into the victim's e-mail or Facebook account. Doing so was inappropriate even if the defendant merely just looks around, given the amount of private information stored in email and Facebook accounts. It was even worse to publish content under that person's name, and worse still to post fake come-ons for sex.
Having said this, once a juvenile finds out he/she can access to a peer's Facebook account, it seems like it would be almost irresistible not to muck around with it. I don't want to dismiss this entirely as "kids will be kids," but I'm sure a nontrivial percentage of kids would take advantage of a peer's password if the circumstance presented itself. Perhaps it's like the joyriding of days of old. If people left keys in their cars, some kids would take the cars for a spin. We can enact draconian laws to discourage joyriding, but if keys are left in cars, joyrides are inevitable. Here, the defendant basically took the victim's Facebook account for a joyride. It was unquestionably wrong behavior, but given its inevitability, it probably shouldn't be felonious.
The defendant's behavior here is analogous to the fake online profiles that teens set up for school officials. I blogged in more detail about that phenomenon last year. In connection with the DC v. RR case, I also blogged on the problems of kids saying hyperbolically outrageous things online that aren't amenable to punishment under traditional defamation or bullying laws. All of these examples remind us that kids are going to push limits with electronic tools just like they do offline. We need to find safer ways to let kids be kids online without ruining their lives.
Part three: The court stretched the identity theft statute too far. As Venkat recaps, the court confronted several statutory ambiguities without any good common law precedent. The court also didn't acknowledge or consider any constitutional concerns with its ruling. Instead, the court reaches the counterintuitive and potentially troubling result that publishing fake content through someone else's account steals their identity. Obviously that takes us a pretty far distance from a paradigmatic case of pretending to be someone for commercial benefit (i.e., what I typically think of as "theft").
As Venkat indicates, the ruling reinforces why we should be nervous about California's recent "e-personation" law, which is even more broadly written and applies even when there's no password misuse. It also shows why expansive identity theft laws should be feared, not encouraged. For more on that point, see my post about Illinois' identity theft law.
This ruling leaves open two obvious questions:
- Will it always be identity theft to use a third party password to publish fake content via someone else's account?
- Will it be identity theft to access a third party or shared computer and publish fake content via someone else's account? In that case, the password isn't obtained at all. Given how many people always leave their computers logged in to various services, I imagine this happens with some frequency.
Vilnius Mayor A.Zuokas Fights Illegally Parked Cars with Tank
<ATTN: Pistoliero... you'll like this one.>
20110801
Another Day, Another Study That Says 'Pirates' Are The Best Customers... This Time From HADOPI
We've pointed out that a whole series of studies have all suggested that the biggest infringers of content online also tend to be the best customers of content, rather than just "freeloaders" who refuse to pay for content. Critics of these studies brush them off (without any evidence) by simply saying if that were true, then sales of content wouldn't have dropped so much in the music industry (other industries, it should be noted, have not seen such a drop-off). But that's misunderstanding (or misapplying) basic statistics. No one is saying that this means that file sharing automatically leads to more sales. But it does suggest that treating those people as just "freeloaders who just want stuff for free" is absolutely the wrong response. It shows that these people are willing to pay money if they're given a good reason to buy. The problem is that they're not.
From a strategic standpoint, this impacts how one responds to increased "piracy." If you realize that they're merely underserved customers, the correct response is to come up with better business models. If the problem is that it's "free, free, free!" then perhaps enforcement could make some sense. But... all of the studies seem to suggest it's the former, rather than the latter... and thus the enforcement/stricter copyright responses won't help at all (as we've seen).Joe Karaganis, from SSRC, points us to the news that there's been yet another such study... and this one is from HADOPI, itself. Yes, the French agency put together to kick people off the internet for file sharing did a study on the nature of unauthorized file sharing, too. Not surprisingly (and consistent with every other study we've seen on this topic), it found that those who spend a lot of money on content... were much, much, much more likely to also get content through unauthorized means. HADOPI released the results in a somewhat convoluted way (perhaps trying to downplay this result), but Karaganis reformatted the results to make this clear:
If piracy is a sampling and discovery tool for high spenders, then suppressing piracy could depress legal sales. If–as I’ll argue at more length in a subsequent post–we’re in a mostly zero-sum market in which consumers are maxed out on discretionary media expenditures, then enforcement won’t significantly expand but at best just cannibalize one media sector for another. Music, games, and movies, let’s say, competing for the same discretionary dollars–and all of them competing with rising, increasingly non-discretionary internet access and data charges. If we’re in this type of market, then HADOPI is just in the business of eliminating its best customers. Good luck with that business model.And suppressing the means of communication at the same time -- collateral damage for no good purpose. Brilliant!
Official London anti-terrorist publication says anarchists should be reported to local police
The City Of Westminster Counter Terrorist Focus Desk publishes a weekly briefing on safety called Griffin Weekly, full of useful advice. For example, this week’s briefing contains these helpful tips on Anarchism: “Anarchism is a political philosophy which considers the state undesirable, unnecessary, and harmful, and instead promotes a stateless society, or anarchy. Any information relating to anarchists should be reported to your local Police.”
Right, that’s my weekend sorted — I’ll be down at my local police station, reading the works of Kropotkin aloud for the constables.
(More seriously: Seriously? These are the terrorism experts who are making official evaluations of risk and official plans to mitigate it? Seriously?)